Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11, 17.x before 17.02.9, and 17.11.x before 17.11.0rc2, allowing privilege escalation to root during Prolog or Epilog execution.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:schedmd:slurm:*:*:*:*:*:*:*:*",
"cpe:2.3:a:schedmd:slurm:17.11.0:rc1:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "17.02.0"
},
{
"fixed": "17.2.09"
},
{
"last_affected": "17.11.0-rc1"
}
],
"source": "CPE_FIELD",
"vendor_product": "schedmd:slurm"
}
]
}